User registration & user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)
unknown
[en] Incorrect Privilege Assignment vulnerability in Userplus UserPlus allows Privilege Escalation.This issue affects UserPlus: from n/a through 2.0.
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2024
CVE-2024-52442 on NVD →
UserPlus <= 2.0 - Privilege Escalation
critical
The User registration & user profile – UserPlus plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to gain administrator privileges.
- CVSS:
- 9.8
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 18, 2024
CVE-2024-52442 on NVD →
User registration & user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)
unknown
[en] The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' p...
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2024
CVE-2024-9518 on NVD →
User registration & user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)
unknown
[en] The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or...
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2024
CVE-2024-9520 on NVD →
User registration & user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)
unknown
[en] The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration...
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 10, 2024
CVE-2024-9519 on NVD →
UserPlus <= 2.0 - Unauthenticated Privilege Escalation
critical
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parame...
- CVSS:
- 9.8
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 9, 2024
CVE-2024-9518 on NVD →
UserPlus <= 2.0 - Authenticated (Editor+) Registration Form Update to Privilege Escalation
high
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration form...
- CVSS:
- 7.2
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 9, 2024
CVE-2024-9519 on NVD →
UserPlus <= 2.0 - Missing Authorization via Multiple Functions
medium
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or dele...
- CVSS:
- 6.3
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 9, 2024
CVE-2024-9520 on NVD →
User registration & user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)
unknown
[en] The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 16, 2024
CVE-2023-0824 on NVD →
UserPlus <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
The UserPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to modify plugin options, including injecting malicious JavaScript into the plugin options, via a forged reques...
- CVSS:
- 6.1
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Apr 12, 2023
CVE-2023-0824 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database